Update dependency pymongo to v4.6.3 [SECURITY]#74
Open
renovate[bot] wants to merge 1 commit into
Open
Conversation
2676804 to
00036fd
Compare
00036fd to
5fa1b0e
Compare
92081c1 to
a681bee
Compare
a681bee to
05bf5bf
Compare
05bf5bf to
8a0c1d9
Compare
8a0c1d9 to
b79d186
Compare
755264d to
366c03b
Compare
366c03b to
da6b80d
Compare
da6b80d to
a71fa48
Compare
a71fa48 to
b4341c0
Compare
b4341c0 to
b48a0f3
Compare
b48a0f3 to
894bd47
Compare
Contributor
Author
|
894bd47 to
8f5adfb
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
4.4.0→4.6.3==4.4.0→==4.6.3PyMongo Out-of-bounds Read in the bson module
CVE-2024-5629 / GHSA-m87m-mmvp-v9qm
More information
Details
Versions of the package pymongo before 4.6.3 are vulnerable to Out-of-bounds Read in the bson module. Using the crafted payload the attacker could force the parser to deserialize unmanaged memory. The parser tries to interpret bytes next to buffer and throws an exception with string. If the following bytes are not printable UTF-8 the parser throws an exception with a single byte.
Severity
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:N/A:LReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
Release Notes
mongodb/mongo-python-driver (pymongo)
v4.6.3: PyMongo 4.6.3Compare Source
Community notes: https://www.mongodb.com/community/forums/t/pymongo-4-6-3-release-for-cve-2024-5629/284348
v4.6.2: PyMongo 4.6.2Compare Source
Release notes: https://www.mongodb.com/community/forums/t/pymongo-4-6-2-released/267404
v4.6.1: PyMongo 4.6.1Compare Source
Release notes: https://www.mongodb.com/community/forums/t/pymongo-4-6-1-released/255752
v4.6.0: PyMongo 4.6.0Compare Source
Release notes: https://www.mongodb.com/community/forums/t/pymongo-4-6-0-released/251866
v4.5.0: PyMongo 4.5.0Compare Source
Release notes: https://www.mongodb.com/community/forums/t/pymongo-4-5-0-released/240662
v4.4.1: PyMongo 4.4.1Compare Source
Release notes: https://www.mongodb.com/community/forums/t/pymongo-4-4-1-released/235045
Configuration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about these updates again.
This PR was generated by Mend Renovate. View the repository job log.